diff options
author | Marcel Holtmann <marcel@holtmann.org> | 2010-03-15 17:12:58 -0400 |
---|---|---|
committer | Marcel Holtmann <marcel@holtmann.org> | 2010-03-21 00:49:32 -0400 |
commit | 101545f6fef4a0a3ea8daf0b5b880df2c6a92a69 (patch) | |
tree | 5b4254a64db65f1958a36ec6955dbba1b71031a7 /net/bluetooth/rfcomm/sock.c | |
parent | af98441397227a5a4f212cd48710eea72a14dbdb (diff) |
Bluetooth: Fix potential bad memory access with sysfs files
When creating a high number of Bluetooth sockets (L2CAP, SCO
and RFCOMM) it is possible to scribble repeatedly on arbitrary
pages of memory. Ensure that the content of these sysfs files is
always less than one page. Even if this means truncating. The
files in question are scheduled to be moved over to debugfs in
the future anyway.
Based on initial patches from Neil Brown and Linus Torvalds
Reported-by: Neil Brown <neilb@suse.de>
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
Diffstat (limited to 'net/bluetooth/rfcomm/sock.c')
-rw-r--r-- | net/bluetooth/rfcomm/sock.c | 11 |
1 files changed, 10 insertions, 1 deletions
diff --git a/net/bluetooth/rfcomm/sock.c b/net/bluetooth/rfcomm/sock.c index ca87d6ac6a20..8d0ee0b8a6b6 100644 --- a/net/bluetooth/rfcomm/sock.c +++ b/net/bluetooth/rfcomm/sock.c | |||
@@ -1068,13 +1068,22 @@ static ssize_t rfcomm_sock_sysfs_show(struct class *dev, | |||
1068 | struct sock *sk; | 1068 | struct sock *sk; |
1069 | struct hlist_node *node; | 1069 | struct hlist_node *node; |
1070 | char *str = buf; | 1070 | char *str = buf; |
1071 | int size = PAGE_SIZE; | ||
1071 | 1072 | ||
1072 | read_lock_bh(&rfcomm_sk_list.lock); | 1073 | read_lock_bh(&rfcomm_sk_list.lock); |
1073 | 1074 | ||
1074 | sk_for_each(sk, node, &rfcomm_sk_list.head) { | 1075 | sk_for_each(sk, node, &rfcomm_sk_list.head) { |
1075 | str += sprintf(str, "%s %s %d %d\n", | 1076 | int len; |
1077 | |||
1078 | len = snprintf(str, size, "%s %s %d %d\n", | ||
1076 | batostr(&bt_sk(sk)->src), batostr(&bt_sk(sk)->dst), | 1079 | batostr(&bt_sk(sk)->src), batostr(&bt_sk(sk)->dst), |
1077 | sk->sk_state, rfcomm_pi(sk)->channel); | 1080 | sk->sk_state, rfcomm_pi(sk)->channel); |
1081 | |||
1082 | size -= len; | ||
1083 | if (size <= 0) | ||
1084 | break; | ||
1085 | |||
1086 | str += len; | ||
1078 | } | 1087 | } |
1079 | 1088 | ||
1080 | read_unlock_bh(&rfcomm_sk_list.lock); | 1089 | read_unlock_bh(&rfcomm_sk_list.lock); |